Improper Access Control on view student list in 4jean/lav_sms
Reported on
Apr 17th 2022
Description
lav_sms system provide a feature for teachers to view any student in the systems. The problem is when student also can view the student's list. They also can download the list in pdf or excel.
Proof of Concept
1. GET http://lav_sms.test/students/list/{id}
Step to reproduce
1. Login as student
2. navigate to /students/list/{id}
Impact
Student could gather the information about other student such as email, photo and adm_no
Occurrences
SECURITY.md
2 years ago
Thanks for your report. Would fix this issue promptly
@4jean - are you able to resolve
the report (valid and fixed)?